uBlock Origin Scope
The AI review rates the findings as likely false positive, but the risk score (44/100) still counts them.
Analysis record
- Analysed
- Today
- Version
- v1.5.1
- Artifact
- SHA256 DAD…888
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidencePublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
9 permissionsIntercept, modify, and block all network requests
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This extension is published by "[email protected]" — the actual developer email for Raymond Hill, creator of the legitimate uBlock Origin ad blocker. Despite the high finding count (32 high-severity items), all "malware-signature" findings are postinstall_* YARA rules (postinstall_file_manipulation, postinstall_obfuscation, postinstall_network_communication, postinstall_file_download, postinstall_crypto_operations) on "unknown_file". Per documented CVEQ false-positive patterns, these postinstall_* rules match basic Node.js patterns like fetch, exec, fs, and crypto operations, and are classified as code-smell rather than actual malware signatures.
The two network findings are benign: js/lib/publicsuffixlist.js:567 contains a fetch call to the publicsuffixlist library (a legitimate utility for domain parsing), and js/background.js:86 contains a standard fetch operation in the background script. Neither finding references suspicious domains — both are generic fetch calls without malicious destinations.
The threat_indicators metadata confirms zero actual malware signatures, zero obfuscation findings, and zero suspicious IoCs. The 32 high-severity items are all code-smell findings masquerading as malware-signature due to CVEQ's scoring system, which is a known issue that disproportionately inflates risk scores.
A skeptic might argue that the extension name "uBlock Origin Scope" differs from the official "uBlock Origin" and could indicate typosquatting. However, the developer attribution to Raymond Hill's verified email address strongly indicates this is either an official variant or a legitimate related project from the same developer. The description "A tool which reports remote server connections" suggests a diagnostic utility rather than ad-blocking, which is consistent with a scope-testing tool from the uBlock Origin ecosystem. Without evidence of credential theft, data exfiltration to suspicious domains, or actual malware signatures, the findings represent false positives from known CVEQ noise patterns.
Key Reasons
- Developer email [email protected] belongs to Raymond Hill, creator of legitimate uBlock Origin
- All malware-signature findings are postinstall_* YARA rules on unknown_file, known false-positive patterns
- Network findings are generic fetch calls in legitimate files without suspicious domains
- Threat indicators show zero actual malware signatures, zero obfuscation, zero suspicious IoCs
False Positive Considerations
- postinstall_* YARA rules matching Node.js patterns
- Generic fetch calls flagged as network findings
- Unknown_file paths for code-smell matches
- Score inflation from code-smell categorized as high-severity
Reviewed 2026-05-23; recommended action: suppress false positive; model confidence 85%.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
uBlock Origin Lite
Raymond Hill
uBlock Origin Lite
[email protected]
JSaw Puzzle
[email protected]
Edge Translate - Browser Translator | PDF Translation | MV3 | Open Source
[email protected]
Intelbras Cloud
[email protected]
SlingPlayer for DISH Anywhere
Unknown Developer